T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:43- Finding
Remote Installer Is Executed Directly Through curl-to-shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent registry purpose, but it should be reviewed carefully because it can persistently pull remote instructions and updates, start background telemetry, and expose unsafe remote-execution paths.
Install only if you fully trust the SkillNote backend and are comfortable with it influencing future agent instructions, receiving skill-usage telemetry with session identifiers, and controlling updates. Prefer HTTPS, disable or remove the watcher if telemetry is not wanted, avoid curl-to-shell installation, and require manual review of synced skills and updates before using them.
SKILL.md:43Remote Installer Is Executed Directly Through curl-to-shell
sync.sh:132Backend-Controlled Skill Content Is Persistently Loaded as Agent Instructions
sync.sh:31Remote HTTP Response Is Interpolated into Python Source Code
sync.sh:31Unsigned Backend-Controlled Automatic Self-Update Channel
log-watcher.py:29Persistent Daemon Monitors All Agent Session Logs and Transmits Identifiers
sync.sh:132Unsanitized Registry Slug Controls Filesystem Paths and Generated Shell Commands
The documented presence of a local VERSION marker specifically for self-update indicates the skill is designed to update itself. In this skill's context, self-update is dangerous because later sections state updates are fetched from a user-configured host and can result in clawhub install ... --yes or overwriting SKILL.md, creating a remote code/instruction supply-chain path.
~/.openclaw/skills/skillnote/sync.sh sync + daemon launcher (executable) ~/.openclaw/skills/skillnote/log-watcher.py analytics daemon ~/.openclaw/skills/skillnote/config.template.json config skeleton ~/.openclaw/skills/skillnote/VERSION local version marker for self-update
## Files this bundle creates at runtime
This runtime behavior confirms the bundle writes mirrored skills into ~/.openclaw/skills/sn-<slug>/SKILL.md and maintains self-update state. In context, this means remote registry content is continuously materialized into agent-consumable instruction files, so a compromised or malicious registry can push new agent behavior without a normal installation review step.
| `~/.openclaw/skills/skillnote/config.json` | SKILL.md Step 3 (agent writes after asking user) | Stores resolved registry URL + user_id |
| `~/.openclaw/skills/sn-<slug>/SKILL.md` | sync.sh (every 60s) | Mirrors of registry skills, one dir per slug |
| `~/.openclaw/skills/skillnote/.last-sync-time` | sync.sh | Sync throttle marker |
| `~/.openclaw/skills/skillnote/.last-version-check` | sync.sh | Self-update throttle marker (24h) |
| `~/.openclaw/skills/skillnote/.log-watcher-state.json` | log-watcher.py | Tracks file offsets + seen skill slugs for dedup |
| `~/.openclaw/skills/skillnote/.log-watcher.log` | sync.sh (stderr redirect of daemon) | Daemon stderr log |
| `~/.openclaw/skills/skillnote/.sync.lock/` | sync.sh | Single-writer mkdir lock |
The documented GET /v1/openclaw-skill self-update check is a direct remote update channel. Because the skill also states all requests go to a configurable host and the update can trigger installation or overwrite behavior, this creates a classic supply-chain risk where a hostile backend or MITM on insecure transport can change the skill's future behavior.
|---|---|---|---|
| `GET /v1/skills?limit=1` | On agent setup once | Reachability check | none |
| `GET /v1/skills` | Every 60s (sync.sh) | Fetch skill catalog | none |
| `GET /v1/openclaw-skill` | Every 24h (sync.sh) | Self-update version check | none |
| `POST /v1/hooks/skill-used` | Per skill read (log-watcher.py) | Implicit analytics event | `{skill_slug, session_id, agent_name}` |
The bundle posts:
The skill presents itself as a registry/feedback helper, but the body directs self-updates, a log-watcher daemon, sidecar instruction injection, and broad task-triggering behavior not surfaced in the summary. Hidden or minimized behavior is especially dangerous in an always: true skill because it is loaded persistently and can shape future agent actions.
The skill presents itself as a registry/feedback helper, but the body directs self-updates, a log-watcher daemon, sidecar instruction injection, and broad task-triggering behavior not surfaced in the summary. Hidden or minimized behavior is especially dangerous in an always: true skill because it is loaded persistently and can shape future agent actions.
Referenced artifact was not completely inspected
This `SKILL.md` lives at `~/.openclaw/skills/skillnote/` and arrived via one of:
Referenced artifact was not completely inspected
This `SKILL.md` lives at `~/.openclaw/skills/skillnote/` and arrived via one of:
Referenced artifact was not completely inspected
This `SKILL.md` lives at `~/.openclaw/skills/skillnote/` and arrived via one of:
curl ... | bash is a classic arbitrary code execution pattern: it downloads a script from a remote server and executes it immediately without review or integrity verification. In this skill, that installer is specifically recommended for recovery/reinstallation, so a compromised backend or MITM could fully compromise the host.
clawhub install skillnote
curl -sf $SKILLNOTE_BASE_URL/setup/agent | bash -s -- --agent openclaw
The skill defines an automatic self-update workflow that checks a remote endpoint daily and changes the locally installed skill based on the response. Any compromise of the backend, update channel, or transport could push new instructions or code into an always: true skill, creating a persistent remote code and policy injection mechanism.
---
# Daily self-update check
`sync.sh` does this automatically every 24 hours (tracked via `~/.openclaw/skills/skillnote/.last-version-check`):
This line is the most dangerous part of the update flow: it authorizes overwriting SKILL.md and VERSION directly from remote content, or reinstalling via clawhub. Because SKILL.md controls future agent behavior, a malicious update can silently persist altered instructions, telemetry, or destructive commands across sessions.
- If `clawhub` is on PATH: `clawhub install skillnote@<ver>`
- Otherwise: overwrite `SKILL.md` + `VERSION` inline from the response
You don't need to do anything for self-updates. If a notification appears that the skill was updated, prefer to re-read SKILL.md before continuing — the steps may have changed.
---
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Open
~/.openclaw/workspace/AGENTS.mdand delete the line@include ~/.openclaw/skillnote-agents.md. (I won't auto-edit your AGENTS.md.)
rm -f ~/.openclaw/skillnote-agents.md
clawhub is on PATH: clawhub uninstall skillnoteTool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
4. **Remove the skill files:**
- If `clawhub` is on PATH: `clawhub uninstall skillnote`
- Otherwise: `rm -rf ~/.openclaw/skills/skillnote`
5. **Optional** (frees disk; loses synced skills): `rm -rf ~/.openclaw/skills/sn-*`
6. **Confirm to the user:**
> SkillNote removed. Daemon stopped, sidecar deleted, skill files removed. One thing left: delete the `@include` line from your AGENTS.md.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
4. **Remove the skill files:**
- If `clawhub` is on PATH: `clawhub uninstall skillnote`
- Otherwise: `rm -rf ~/.openclaw/skills/skillnote`
5. **Optional** (frees disk; loses synced skills): `rm -rf ~/.openclaw/skills/sn-*`
6. **Confirm to the user:**
> SkillNote removed. Daemon stopped, sidecar deleted, skill files removed. One thing left: delete the `@include` line from your AGENTS.md.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
4. **Remove the skill files:**
- If `clawhub` is on PATH: `clawhub uninstall skillnote`
- Otherwise: `rm -rf ~/.openclaw/skills/skillnote`
5. **Optional** (frees disk; loses synced skills): `rm -rf ~/.openclaw/skills/sn-*`
6. **Confirm to the user:**
> SkillNote removed. Daemon stopped, sidecar deleted, skill files removed. One thing left: delete the `@include` line from your AGENTS.md.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
4. **Remove the skill files:**
- If `clawhub` is on PATH: `clawhub uninstall skillnote`
- Otherwise: `rm -rf ~/.openclaw/skills/skillnote`
5. **Optional** (frees disk; loses synced skills): `rm -rf ~/.openclaw/skills/sn-*`
6. **Confirm to the user:**
> SkillNote removed. Daemon stopped, sidecar deleted, skill files removed. One thing left: delete the `@include` line from your AGENTS.md.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
4. **Remove the skill files:**
- If `clawhub` is on PATH: `clawhub uninstall skillnote`
- Otherwise: `rm -rf ~/.openclaw/skills/skillnote`
5. **Optional** (frees disk; loses synced skills): `rm -rf ~/.openclaw/skills/sn-*`
6. **Confirm to the user:**
> SkillNote removed. Daemon stopped, sidecar deleted, skill files removed. One thing left: delete the `@include` line from your AGENTS.md.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
4. **Remove the skill files:**
- If `clawhub` is on PATH: `clawhub uninstall skillnote`
- Otherwise: `rm -rf ~/.openclaw/skills/skillnote`
5. **Optional** (frees disk; loses synced skills): `rm -rf ~/.openclaw/skills/sn-*`
6. **Confirm to the user:**
> SkillNote removed. Daemon stopped, sidecar deleted, skill files removed. One thing left: delete the `@include` line from your AGENTS.md.
The declared self-update capability is itself a meaningful risk signal because it indicates the component is designed to replace or modify itself over time. In a skill whose role is primarily content synchronization, that capability increases the blast radius of any server compromise or trust failure.
#!/bin/bash
# SkillNote Sync for OpenClaw
# 1. Skills sync — every 60s: fetch all skills → write sn-{slug}/SKILL.md
# 2. Self-update — every 24h: compare versions → auto-install if newer
export PYTHONIOENCODING=utf-8
The self-update check initiates a control flow where remote version metadata determines whether local state will be changed. That establishes a remote-controlled modification mechanism that is inappropriate without strong integrity checks and user authorization.
NOW=$(date +%s)
# ── Self-update check (daily) ─────────────────────────────────────────────────
VERSION_CHECK_FILE="$SKILLNOTE_DIR/.last-version-check"
VERSION_FILE="$SKILLNOTE_DIR/VERSION"
The script's documented purpose is syncing skills and collecting feedback, but it also performs a remote self-update path that can install a new package or overwrite local skill content based on server-provided data. This expands trust from 'sync content' to 'execute remote lifecycle changes', creating a significant supply-chain and unauthorized capability escalation risk if the server or transport is compromised.
The script overwrites local skill content from a remote response during self-update, which is direct self-modification based on network input. This is dangerous because a compromised or spoofed server can change the trusted local instruction set and influence future agent behavior without a separate review step.
clawhub install "skillnote@$REMOTE_VER" --yes >/dev/null 2>&1 && \
echo "SkillNote updated to v$REMOTE_VER — restart your session to apply."
else
# clawhub unavailable — overwrite SKILL.md + sync.sh from server response
SKILL_BODY=$(echo "$REMOTE" | python3 -c "import json,sys; print(json.load(sys.stdin).get('skill',''))" 2>/dev/null)
if [ -n "$SKILL_BODY" ]; then
echo "$SKILL_BODY" > "$SKILLNOTE_DIR/SKILL.md"
The script launches a background log-watcher daemon over agent directories even though the skill is described as a registry sync tool. Monitoring agent directories in the background broadens data access and persistence, and can expose session metadata or sensitive workflow data beyond what users would reasonably expect from skill synchronization.
Writing the skillnote-agents.md sidecar modifies the agent's local instruction environment and is a form of self-directed persistence. Even though it avoids directly editing AGENTS.md, it still plants policy content intended for inclusion in future sessions, which can alter behavior and increase remote reporting obligations.
fi
fi
# ── Write skillnote-agents.md sidecar (idempotent, runs every sync) ───────────
# We write instructions to a SIDECAR file the user @includes from their own
# AGENTS.md (one-time setup; see SKILL.md). We do NOT modify
# ~/.openclaw/workspace/AGENTS.md directly. Two reasons:
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
~/.openclaw/skills/skillnote/SKILL.md agent instructions (always: true)
~/.openclaw/skills/skillnote/sync.sh sync + daemon launcher (executable)
~/.openclaw/skills/skillnote/log-watcher.py analytics daemon
~/.openclaw/skills/skillnote/config.template.json config skeleton
Detected: suspicious.destructive_delete_command